首页> 外国专利> CLOUD-BASED ORCHESTRATION OF INCIDENT RESPONSE USING MULTI-FEED SECURITY EVENT CLASSIFICATIONS WITH MACHINE LEARNING

CLOUD-BASED ORCHESTRATION OF INCIDENT RESPONSE USING MULTI-FEED SECURITY EVENT CLASSIFICATIONS WITH MACHINE LEARNING

机译:基于Cloud的事件响应响应的响应,使用机器学习进行多馈安全事件分类

摘要

Systems and methods for performing multi-feed classification of security events to facilitate automated IR orchestration are provided. According to one embodiment a cloud-based security service protecting a private network provides a plurality of data feeds, wherein each data feed of the plurality of data feeds independently classify a given security event and produce a classification result. In response to an event associated with a process of an endpoint device that is part of the private network an endpoint protection platform running on the endpoint device performs an initial classification of the event and transmits the classification result to the cloud-based security service for final classification to facilitate causing, by the cloud-based security service, the endpoint protection platform to perform an automated incident response, by providing an output of an automated response engine of the cloud-based security service to the endpoint protection platform.
机译:提供了用于执行安全事件的多馈送分类以便于促进自动IR编排的系统和方法。根据一个实施例,保护专用网络的基于云的安全服务提供多个数据馈送,其中多个数据馈送的每个数据馈送独立地分类给定的安全事件并产生分类结果。响应于与作为专用网络的一部分的端点设备的过程相关联的事件,该事件在端点设备上运行的端点保护平台执行事件的初始分类,并将分类结果发送到最终的基于云的安全服务通过基于云的安全服务,通过向端点保护平台提供基于云的安全服务的自动响应引擎的输出,通过基于云的安全服务来实现自动化事件响应的端点保护平台来进行分类。

著录项

  • 公开/公告号US2021176261A1

    专利类型

  • 公开/公告日2021-06-10

    原文格式PDF

  • 申请/专利权人 FORTINET INC.;

    申请/专利号US201916709331

  • 发明设计人 UDI YAVO;ROY KATMOR;IDO KELSON;

    申请日2019-12-10

  • 分类号H04L29/06;G06N20;G06K9/62;

  • 国家 US

  • 入库时间 2022-08-24 19:07:02

获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号